The Protiviti View  | Insights From Our Experts on Trends, Risks and Opportunities

The Protiviti View

Insights From Our Experts on Trends, Risks and Opportunities
Search

POST

4 mins to read

Tips for a Fraud-Free Holiday Season

Larger Font
4 minutes to read

The festive season is a time for fun and good cheer. Your business is celebrating the end of the calendar year and staff are counting down the days before their extended holidays begin. But be warned – the holidays are also a peak season for cybercriminals and fraudsters looking to exploit your vulnerabilities at a time of skeleton staffing and “go slow” activity.

Protiviti has found that a significant number of frauds come to light in the new year and the last thing you want is for your business to become a casualty to an enterprising fraudster. We suggest the tips below to help you achieve a fraud-free holiday season.

Before you go on your break, actively consider the following:

Be Proactive

  • Arrange for key staff to be available or on call over the holiday period to cope with unforeseen circumstances. Produce a schedule showing which members of staff are expected to work and give it to the security team. Ask the security team to report any unexpected people visiting the office, as well as any late night or weekend work.
  • If you employ temporary staff over the holiday period, particularly in key areas such as security or IT, try to ensure that at least one permanent member of staff is always present.
  • Make sure temporary staff references and details are thoroughly examined and verified prior to commencement.

Update the Response Strategy

  • Prepare a fraud response plan, with details of key advisers and other parties such as accountants, lawyers, police, insurers and bankers, so that you know what to do and who to contact if the worst happens. Produce a list for key personnel that includes their whereabouts during the holiday period, their dates of availability and contact details so that they can be reached in an emergency.

Pay Attention to Physical Security

  • Ensure all key documents are adequately secured, with duplicated copies off-site.
  • Let local police know if your offices and other buildings are to be closed and unattended during the holidays. Do not solely rely on alarm systems.

Ensure Data Is Secure

  • Make sure any IT and security devices, such as server back-ups and video security DVR or cloud storage, have sufficient storage media to last the whole holiday period. Ensure back-up tapes of critical IT systems are duplicated, with copies being maintained off-site.
  • Consider limiting access rights to key computer systems to essential personnel only. Consider disabling remote access to your IT systems over the holiday period, especially if you have no permanent staff monitoring access. If remote access is necessary, implement multifactor authentication for remote users and devices to enhance security.
  • Assess the most common or trending cyber exploitation techniques and ensure your systems can withstand them. Ensure all recommended vendor patches are integrated and up to date and that all firewalls, intrusion detection and anti-virus systems are working effectively.
  • Remind staff of their important role in data security. Caution them about lost laptops, the integrity of PINs and passwords, and recognising malware scams and suspicious (phishing) emails. Ask them to keep their eyes open for any unusual activity and to report anything suspicious immediately. True, this is a year-round imperative, but enhanced vigilance is warranted during the holiday season.
  • Ensure you have a comprehensive and up-to-date cybersecurity response and communication plan that is ready to be deployed should a data breach occur. Make sure key members of your cyber response team are aware of their responsibilities and can be contacted even while on leave.

Establish Proper Authorities

  • Ensure your bank will not process transactions over a given amount without first obtaining authority from a senior member of staff. You may need to give your bank manager your personal contact details.
  • Ensure someone with the appropriate authority level is always present to approve transactions. Don’t let standards drop just because it’s the festive season.
  • Do NOT pre-sign blank cheques or authorisation forms to cover the holiday period.
  • Scrutinise any requests for “urgent” transactions. Query requests for unusual actions such as manual cheques and miscellaneous account coding.

On returning to the office, you should follow up in the following areas:

Reinforce Accountability

  • Meet with the security team to learn of any unusual events and attendances.
  • Review telephone logs for details of calls that took place at unusual times. Follow up on any unexplained absences from work. Fraudsters can often make themselves scarce immediately after committing the fraud.
  • Review any journal entries that have been processed in the previous month.

Scrutinise for Irregularities

  • Review changes to all master files to ensure they are bona fide. Scrutinise system access logs for unusual patterns.
  • Review all bank statements and perform bank reconciliations as soon as possible after your return. Ensure all reconciling items are valid.
  • Look out for severe changes in behaviour, personality and working practices of any staff members. Concealing a fraud is stressful and the red flags will soon appear.
  • Before all security settings are returned to normal, consider reviewing them for appropriateness with respect to the levels of access granted to staff.
  • Carry out a review of all security measures – both physical and IT. Identify and investigate all breaches.

Finally, Listen

  • Listen to the grapevine. There’s often an element of truth in office rumour. All allegations and suspicions should be thoroughly investigated.

With some common sense precautions, preparation and planning, you and your staff can enjoy “the most wonderful time of the year” without letting your guard down on fraud risk. Happy Holiday!

Was this post helpful to you?

Thanks for your feedback!

Subscribe to The Protiviti View Blog

To face the future confidently, you need to be equipped with valuable insights that align with your interests and business goals.

In this Article

Find a similar post by topics

Authors

Anthony Hodgkinson

By Anthony Hodgkinson

Verified Expert at Protiviti

EXPERTISE

No noise.
Just insights.

Subscribe now

Related posts

Article

What is it about

While the return-to-office decision is often framed in a straightforward manner — we believe collaboration, productivity and innovation flourish more...

Article

What is it about

What you need to know: Aging systems, data silos, regulatory pressures and talent gaps complicate enterprise transformation for public utilities....

Article

What is it about

The top priority for healthcare internal auditors this year is cybersecurity, according to a survey by Protiviti and the Association...

Search